{"id":"a5d5d1b8-ae8e-4385-b011-68dcab167674","arxiv_id":"2607.26856","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.5,"correctness_risk":"high","formal_verification":"none","parameter_count":6,"one_line_summary":"Modifying COW-QKD to test CHSH correlations instead of adjacent-pulse coherence yields simulated secure distances ~259 km and apparent O(η) key-rate scaling.","lead":"A modified coherent-one-way QKD protocol replaces pulse-coherence checks with CHSH Bell monitoring and an extra decoy state. Simulations then report secure key distribution out to about 259 km with roughly linear loss scaling.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.5","headline":"The linear-rate claim rests on applying Woodhead–Pironio’s qubit-bounded CHSH entropy formula to infinite-dimensional coherent states without a quantitative reduction.","rationale":"The reader correctly isolated the load-bearing gap: the security formula is only as strong as the applicability of Ref. 37’s qubit CHSH bound to this optical prepare-and-measure setting. The optical appendices rigorously realize B1/B2 and recover ideal S=2√2, and the Zenodo simulation is reproducible, but neither closes the dimension/multi-photon gap. No tighter reduction, decoy-style single-photon tagging of the CHSH rounds, or explicit robustness argument against Trenyi–Curty-type zero-error attacks is supplied. That leaves the central claim (secure linear-rate COW out to ~259 km via CHSH monitoring) only partially supported—exactly the CONDITIONAL verdict. My read does not alter it.","tokens_in":17826,"tokens_out":533,"duration_ms":52383,"concrete_test":"Using the exact μ (and f, tB) that generate Figs. 3–4, compute the fidelity of Alice’s four coherent preparations to the nearest qubit encoding in the single-photon time-bin subspace; then check whether a photon-number-splitting / higher-dimensional attack can match the four correlators that define S (and the simulated QBER) while driving Hmin(A|E) strictly below the RHS of Eq. 15. If such an attack exists, the linear-scaling security claim fails inside the paper’s own model.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Eq. 16 sets Hmin(A|E) from the observed monitoring-line S via the Woodhead–Pironio bound (Eq. 15, Ref. 37). That bound is proven only when Alice’s preparations are confined to a qubit. The protocol instead sends weak coherent time-bin states (Eqs. 2, 6–7), with X-basis states only informally approximated (“∼”) for α≪1. The text never quantifies leakage outside the early/late single-photon subspace, multi-photon weight, or the resulting degradation of the entropy bound. Therefore an observed S does not, by the cited theorem, lower-bound Eve’s uncertainty on the data-line key bits, nor does it automatically exclude zero-error-class attacks that exploit the larger Hilbert space. The reported R≈0.002η and 259 km remain simulation outputs under an unverified reduction.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The manuscript proposes a modified coherent-one-way (COW) QKD protocol in which adjacent-pulse coherence monitoring is replaced by a CHSH test in Bob’s monitoring line, together with one additional X-basis decoy state on Alice’s side. Bob’s Mach–Zehnder interferometer is retuned (50:50 + 85:15 beam splitters and a 0/π phase) so that the monitoring line implements the CHSH observables B1=(\\sigma z+\\sigma x)/√2 and B2=(\\sigma z−\\sigma x)/√2. Security is argued via the Woodhead–Pironio prepare-and-measure min-entropy bound Hmin(A|E)≥1−log2(1+√(2−S²/4)) (Eq. 15), yielding the asymptotic rate R≥Qz[1−log2(1+√(2−S²/4))−fEC h(Ez)] (Eq. 16). Simulations with ea=1%, dark-count probability 10−8 and ηd=90% report linear scaling R≈0.002η and a maximum secure distance of ~259 km, substantially beyond recent COW bounds that scale as O(η²).","tokens_in":18021,"tokens_out":1534,"duration_ms":32634,"significance":"If the security reduction holds, the work would restore linear transmittance scaling for a practically relevant DPR protocol and push the simulated secure distance from the sub-20 km / ~100 km regime of recent unconditional analyses to ~259 km, with only modest hardware changes. The optical construction of the CHSH bases (Appendix A) and the explicit ideal correlators giving S=2√2 (Appendix B) are carefully done, and the authors release simulation code and data on Zenodo, which supports reproducibility. The conceptual move—importing a prepare-and-measure CHSH monitor into COW—is interesting and could be useful more broadly. The significance, however, is conditional on a rigorous justification that the qubit-bounded entropy formula applies to the actual coherent-state implementation.","major_comments":[{"comment":"Eqs. (15)–(16) and the citation to Woodhead–Pironio (Ref. 37): the min-entropy bound is proven under an explicit qubit (or bounded-dimension) assumption on Alice’s preparations. The protocol prepares weak coherent time-bin states (Eqs. 2, 6–7), with X states only informally approximated by “∼” for α≪1. The manuscript never quantifies the weight outside the single-photon early/late subspace, the multi-photon component, or the resulting degradation of Hmin(A|E). Without a dimension-reduction or leakage argument, an observed monitoring-line S does not, by the cited theorem, lower-bound Eve’s uncertainty on the data-line key, nor does it automatically rule out zero-error-class attacks that exploit the larger Hilbert space. This reduction is load-bearing for the linear-rate and 259 km claims and must be supplied or the security statement appropriately weakened.","section":"Security Analysis, Eqs. (15)–(16)"},{"comment":"Protocol description / Security Analysis: the text frames the scheme as semi-device-independent and claims detection of a “broader class of potential attacks,” including those that leave adjacent-pulse coherence intact. Under collective i.i.d. attacks the rate formula is standard once Hmin(S) is granted, but the manuscript does not show that CHSH monitoring in the modified line excludes the known zero-error attack of Trenyi–Curty (or analogous attacks) when multi-photon and vacuum components are present. A concrete argument—either a reduction to the qubit case with explicit error terms, or a direct attack analysis under the optical model—is needed to support the central security claim.","section":"Introduction; Security Analysis; Conclusion"},{"comment":"Simulation Results and Figs. 3–4: the reported R≈0.002η and 259 km are obtained by feeding the simulated S(Q) directly into Eq. (16). Because that step inherits the unproven qubit reduction, the numerical comparison with Refs. 28 and 32 (which aim at unconditional or tighter COW analyses) is not yet on equal footing. Either the reduction must be established with quantitative bounds that remain valid at the simulated μ and distances, or the figures should be clearly labeled as performance under the qubit-SDI assumption rather than as an unconditional improvement of COW.","section":"simulation Results, Figs. 3–4"}],"minor_comments":[{"comment":"Eq. (2): the symbol “∼” for the X-basis states should be replaced by an explicit fidelity or trace-distance bound in α, even if only in an appendix, so that the approximation error is trackable.","section":"Protocol description, Eq. (2)"},{"comment":"Fig. 1 caption and main text: the decoy labels |f1⟩, |f2⟩ vs |0x⟩, |1x⟩ are used interchangeably; unify notation.","section":"Fig. 1; §0.3"},{"comment":"The security thresholds S0 and Q0 are mentioned but never specified numerically for the simulations; state the values used to declare a positive key rate out to 259 km.","section":"Modified Protocol; simulation Results"},{"comment":"Finite-key analysis is outlined (smooth min-entropy, leftover hash) but the reported rates are purely asymptotic. A short remark on how finite-size corrections would affect the 259 km figure would help the reader.","section":"§0.4 secret key rate formula"},{"comment":"Typos / style: “notably,” mid-sentence in the Conclusion; “ass-block” in Ref. 24; inconsistent spacing in |α/√2⟩ kets. Also arXiv id 2607.26856 looks nonstandard (year 2607)—verify metadata.","section":"Conclusion; References"},{"comment":"Appendix A: the cyclic identification a′3→a′1 for the virtual mode is fine for vacuum, but a one-line remark that no physical amplitude occupies that mode under the protocol’s two-bin inputs would remove any ambiguity.","section":"Appendix A"}],"recommendation":"major_revision","confidential_remarks":"The optical appendices and code release are genuine strengths; the paper is not empty. The decisive gap is the missing dimension reduction for the Woodhead–Pironio bound. If the authors can supply a quantitative qubit reduction (or switch to a coherent-state security proof that still uses CHSH-type correlators), the result would be suitable for a solid QKD venue. If they cannot, the central claim should be reframed as conditional SDI performance rather than an enhanced unconditional COW proof. I would not reject outright: the hardware idea is clean and the gap is fixable in principle within a revision."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The core move is simple and concrete: add the missing X decoy, retune Bob’s MZI (50/50 + 85/15 and a 0/π phase) so the monitoring line can run B1/B2, then feed the observed CHSH score into the Woodhead–Pironio min-entropy bound and claim linear-like rates out to ~259 km. That is actually new as an engineering adaptation; the optical appendices carefully derive the unitary and recover S = 2√2 in the ideal case, and they put the simulation code on Zenodo. The comparison plots against the quadratic-scaling COW analyses are useful.\n\nThe load-bearing step is soft. Equation 15 is a qubit-bounded SDI result. The protocol sends weak coherent time-bin states and only writes “∼” for the X states when α ≪ 1. There is no quantitative control on multi-photon weight, leakage out of the early/late subspace, or how much the entropy bound degrades. So an observed S does not automatically give you Hmin on the data-line bits the way the cited theorem requires, and it is not shown to close the zero-error-class attacks that motivated the work. The R ≈ 0.002η and 259 km numbers are therefore simulation outputs under optimistic detectors and an unverified reduction, not theorem-level distances. Finite-key and general attacks are left for later.\n\nEverything else (MZI construction, ideal correlators, asymptotic formula once you grant Hmin(S)) looks solid. Citation pattern is normal. This is for people who already care about practical COW fixes or SDI-style monitoring of prepare-and-measure systems. It is worth a serious referee who will force the dimension/multi-photon reduction into the open; I would not desk-reject it. I would read the revision if it appears, but I would not cite the distance claim until the reduction is tightened.","headline":"Modest hardware tweak plus CHSH monitoring gives COW nice simulated range, but the qubit entropy bound is applied to coherent states without a real reduction.","tokens_in":18776,"tokens_out":490,"would_cite":false,"duration_ms":18593,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd","03.67.Hk","42.50.Ex"],"model":"grok-4.5","headline":"Monitoring Bell correlations instead of pulse coherence lets COW quantum key distribution reach about 259 km with linear rate scaling.","keywords":["coherent one-way QKD","COW protocol","CHSH inequality","Bell correlations","semi-device-independent QKD","distributed-phase-reference","secret key rate","quantum key distribution"],"falsifier":"Run the modified protocol over a calibrated loss channel and check whether the measured CHSH value S and QBER produce a positive asymptotic key rate that continues to scale linearly with transmittance out to distances well beyond 20 km; any systematic failure of S to stay above 2, or a return to quadratic scaling, would falsify the claim.","tokens_in":18576,"feed_emoji":"🔑","tokens_out":1004,"duration_ms":17228,"temperature":0.7,"pith_summary":"Coherent one-way quantum key distribution is simple and widely implemented, but its usual security check—watching coherence between successive pulses—fails against certain eavesdropping attacks that leave no bit errors and keep the coherence intact. Those attacks force the secret key rate to scale only as the square of the channel transmittance and have been reported to cap secure distance below 20 km. This paper replaces the coherence monitor with a test of CHSH Bell correlations, adds one extra decoy state on Alice’s side, and retunes Bob’s monitoring interferometer so he can measure the two bases needed for the CHSH test. With those changes the asymptotic key rate is bounded directly by the observed CHSH value S, recovers linear scaling with transmittance, and, in simulation, remains positive out to roughly 259 km. The result matters because it keeps the hardware almost unchanged while restoring a practically usable range for an already-deployed protocol family.","feed_headline":"COW quantum keys reach 259 km by watching Bell correlations","feed_subtitle":"A small optical tweak replaces coherence checks and restores linear rate scaling with distance","key_machinery":"The Woodhead–Pironio min-entropy bound Hmin(A|E) ≥ 1 - log2(1 + √(2 - S²/4)), which converts the observed CHSH parameter S into a lower bound on Eve’s uncertainty and thereby into the key-rate formula R ≥ Qz [1 - log2(1 + √(2 - S²/4)) - fEC h(Ez)].","core_discovery":"Replacing adjacent-pulse coherence monitoring in COW-QKD with a CHSH Bell test (plus one extra decoy state and a retuned Mach–Zehnder interferometer) yields an asymptotic secret-key rate that scales linearly with channel transmittance and extends the simulated secure distance to approximately 259 km.","pith_inferences":["Because the security argument rests on an effective qubit bound, any experimental demonstration must also verify that multi-photon and higher-dimensional leakage remain negligible under the chosen mean photon number.","Finite-key analysis and composable security proofs for the CHSH-monitored COW variant are natural next steps before field deployment.","If the linear scaling holds under realistic detector dark counts and misalignment, metropolitan and short-haul backbone links become realistic targets for upgraded COW systems."],"forward_implications":["Existing COW hardware can be upgraded to longer secure distances by adding one decoy intensity/phase setting and retuning the monitoring interferometer to 85:15 plus a switchable phase.","Secret-key rate recovers linear scaling with channel transmittance (reported R ≈ 0.002 η), matching the scaling of decoy-state BB84 rather than earlier unconditional COW analyses.","Zero-error attacks that preserve pulse coherence but break Bell correlations become detectable through the CHSH monitor.","The same CHSH-monitoring idea can be ported, with only minor optical changes, to other coherent-state or distributed-phase-reference QKD schemes."],"fun_headline_variants":["COW-QKD hits 259 km via CHSH Bell tests instead of coherence","Bell correlations push COW quantum keys to 259 km secure range","CHSH monitoring extends COW-QKD distance to ~259 km","Swap coherence checks for Bell tests: COW keys reach 259 km","COW protocol tweak with CHSH yields 259 km secret-key distance"],"cache_read_input_tokens":128,"weakest_assumption_plain":"The security bound that links CHSH violation to secret-key rate is assumed to apply directly to this infinite-dimensional coherent-state protocol once the weak-pulse X-basis states are treated as approximate qubits.","fun_headline_variants_meta":{"raw":{"variants":["COW-QKD hits 259 km via CHSH Bell tests instead of coherence","Bell correlations push COW quantum keys to 259 km secure range","CHSH monitoring extends COW-QKD distance to ~259 km","Swap coherence checks for Bell tests: COW keys reach 259 km","COW protocol tweak with CHSH yields 259 km secret-key distance"]},"model":"grok-4.5","effort":"low","cost_usd":0.003866,"raw_usage":{"total_tokens":1154,"prompt_tokens":710,"num_sources_used":0,"completion_tokens":86,"cost_in_usd_ticks":38664000,"prompt_tokens_details":{"text_tokens":710,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":358,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":710,"tokens_out":86,"duration_ms":6709,"temperature":1.0,"reasoning_tokens":358,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-30T19:04:07.102768+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Run the modified protocol over a calibrated loss channel and check whether the measured CHSH value S and QBER produce a positive asymptotic key rate that continues to scale linearly with transmittance out to distances well beyond 20 km; any systematic failure of S to stay above 2, or a return to quadratic scaling, would falsify the claim.","supporting_citations":[],"review_version":1}